How to Report Abuse to a Domain Registrar or Hosting Provider (2026)
When you find a phishing site or a domain impersonating your brand, the fastest way to get it removed is to report it to the parties that actually control it: the domain registrar and the hosting provider. Do it with the right contact and the right evidence, and a clear-cut phishing page can come down quickly. Do it sloppily, and the report stalls.
This guide walks through exactly how to report domain abuse — finding the abuse contact, packaging evidence, submitting to the registrar and host, and escalating to ICANN when no one acts.
Registrar vs. hosting provider: who does what
A phishing website almost always involves two separate parties, and you usually report to both:
- The registrar manages the domain name. It can suspend the domain so it stops resolving entirely.
- The hosting provider runs the server where the page lives. It can take the content offline immediately, even if the domain still exists.
Removing the hosting kills the page fastest; suspending the domain stops it from coming back at the same address. Reporting to both gives you the best chance of a quick, durable takedown.
How to report domain abuse, step by step
- Identify the registrar and hosting provider. Look up the domain's WHOIS/RDAP record to find the registrar, and check the hosting provider behind its IP address. A phishing site usually involves both, and each has its own abuse channel.
- Find the abuse contact. Every ICANN-accredited registrar must publish an abuse email address and phone number (RAA Section 3.18), shown in WHOIS results. Hosting providers publish an abuse contact or report-abuse form on their site. Use the published abuse@ address or form, not general support.
- Collect evidence. Capture the full malicious URL, dated screenshots of the phishing page, the domain and hosting details, and a short description of the abuse. Complete evidence submitted the first time is what gets a report actioned quickly.
- Submit the report to the registrar and host. Send the evidence to both the registrar's and the hosting provider's abuse contact. State clearly that the domain is being used for phishing or brand impersonation and request suspension or removal.
- Escalate if there is no action. If a gTLD registrar or registry fails to act, escalate to ICANN Contractual Compliance with proof you contacted them first. Also report to Google Safe Browsing, the APWG, and browser blocklists so users are protected even before the site comes down.
Finding the abuse contact
Every ICANN-accredited registrar is required to publish a dedicated abuse email address and phone number — that obligation comes from Section 3.18 of the Registrar Accreditation Agreement, and the contact appears in the domain's WHOIS/RDAP record. Hosting providers publish their own abuse email or a "report abuse" web form. Always use the official abuse channel; general support or sales queues slow everything down.
You can pull the registrar, hosting, and abuse-contact details for any domain by scanning it with PhishDown, which surfaces WHOIS/RDAP and hosting context in one place so you do not have to chase it across multiple tools.
What a good abuse report contains
A report that gets actioned on the first try includes:
- The exact malicious URL (and any redirect chain).
- Dated screenshots of the phishing or impersonation page.
- The domain, registrar, and hosting details.
- A clear, factual description of the abuse — what brand is impersonated and how.
- For brand owners: proof you own or represent the impersonated brand.
ICANN's step-by-step guidance for DNS abuse complaints recommends the same essentials: screenshots of the abusive behavior, the list of involved domains, and a record that you notified the registrar or registry before escalating.
Escalating when no one acts
If a gTLD registrar or registry ignores a complete report, you can escalate to ICANN Contractual Compliance, including evidence that you contacted them first. Remember that ICANN's authority covers accredited registrars and gTLD registries — not hosting providers, website operators, or other intermediaries. For hosts, escalate to their upstream network provider. In parallel, report to Google Safe Browsing, the APWG, and browser blocklists so users are warned even before the site is removed.
If chasing this for every incident is too much, a managed takedown service runs the whole process — abuse routing, evidence, and escalation — for you. For the broader picture, see our domain and phishing takedown services guide and how to report a phish and take it down instantly.
Frequently asked questions
How do I report a phishing domain to its registrar?
Look up the domain's WHOIS/RDAP record to find the registrar, then send your evidence (the URL, dated screenshots, and a description of the abuse) to the registrar's published abuse email address. Every ICANN-accredited registrar must publish an abuse contact under Section 3.18 of the Registrar Accreditation Agreement.
What is the difference between reporting to a registrar and a hosting provider?
The registrar controls the domain name and can suspend it; the hosting provider controls the server where the content lives and can take the page offline. A phishing site usually involves both, so report to each. Removing the hosting stops the page immediately, while suspending the domain stops it from resolving at all.
Where do I find a provider's abuse contact?
Registrar abuse contacts appear in the domain's WHOIS/RDAP record as a published abuse email and phone number. Hosting providers list a dedicated abuse email or a 'report abuse' form on their website. Use the official abuse channel rather than general support or sales, which slows the report down.
What should a domain abuse report include?
Include the exact malicious URL, dated screenshots of the phishing or impersonation page, the domain and hosting details, and a clear, factual description of the abuse. ICANN's guidance for DNS abuse complaints recommends evidence such as screenshots of the abusive behavior, the list of involved domains, and proof you notified the provider first.
What if the registrar or host ignores my report?
For a gTLD registrar or registry that fails to act, you can escalate to ICANN Contractual Compliance, including proof you contacted them first. ICANN's authority covers accredited registrars and gTLD registries, not hosting providers, so for hosts you escalate to their upstream network provider and to blocklists like Google Safe Browsing.
Sources and further reading
For a real-world example of this process end to end, see PhishEye's IronToll investigation, which walks through reporting a live phishing-as-a-service campaign to its hosting providers and registrar.
- ICANN — Registrar Abuse Reports: registrars must publish an abuse email and phone number (RAA Section 3.18).
- ICANN — Step-by-step guide for submitting DNS abuse complaints: what evidence to collect and how to escalate.
- CISA — Recognize and Report Phishing: official US guidance on reporting phishing.
- APWG — Report phishing: submit phishing to reportphishing@apwg.org.
About the author
Eric Wallace
Security Researcher at PhishDown
Eric researches phishing detection, domain intelligence, and brand-protection takedowns at PhishDown. He writes about how organizations can find and remove phishing sites, lookalike domains, and brand impersonation before they reach customers.
View all articles by Eric Wallace →Why you can trust this guide
- Written and reviewed by PhishDown's security research team.
- Grounded in how phishing detection, domain intelligence, and takedowns actually work in practice, not marketing claims.
- References authoritative sources including CISA, the APWG, ICANN, and the FBI's IC3.
- Last reviewed and updated July 1, 2026.
Related Articles
Find the abuse contact for any domain
PhishDown surfaces registrar, hosting, and abuse-contact details for any URL or domain, then connects confirmed threats to takedown. See how the platform works or get in touch.